Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2024-1551

больше 2 лет назад

Set-Cookie response headers were being incorrectly honored in multipar ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2024-1551

больше 2 лет назад

Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well as control part of the response body, they could inject Set-Cookie response headers that would have been honored by the browser. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-1550

больше 2 лет назад

A malicious website could have used a combination of exiting fullscree ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2024-1550

больше 2 лет назад

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-1549

больше 2 лет назад

If a website set a large custom cursor, portions of the cursor could h ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2024-1549

больше 2 лет назад

If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and unexpected granted permissions. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-1548

больше 2 лет назад

A website could have obscured the fullscreen notification by using a d ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-1548

больше 2 лет назад

A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-1547

больше 2 лет назад

Through a series of API calls and redirects, an attacker-controlled al ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-1547

больше 2 лет назад

Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2024-1551

Set-Cookie response headers were being incorrectly honored in multipar ...

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-1551

Set-Cookie response headers were being incorrectly honored in multipart HTTP responses. If an attacker could control the Content-Type response header, as well as control part of the response body, they could inject Set-Cookie response headers that would have been honored by the browser. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2024-1550

A malicious website could have used a combination of exiting fullscree ...

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-1550

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2024-1549

If a website set a large custom cursor, portions of the cursor could h ...

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-1549

If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and unexpected granted permissions. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2024-1548

A website could have obscured the fullscreen notification by using a d ...

CVSS3: 4.3
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-1548

A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

CVSS3: 4.3
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2024-1547

Through a series of API calls and redirects, an attacker-controlled al ...

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-1547

Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу


Поделиться